First published: Tue Nov 15 2022(Updated: )
Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIPsecTunnelList via the IPsecLocalNet and IPsecRemoteNet parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W15e Firmware | =15.11.0.10\(1576\) | |
Tenda W15E | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41396 is rated as a high severity vulnerability due to its potential to allow remote code execution via command injection.
To mitigate CVE-2022-41396, update the Tenda AC1200 Router Model W15Ev2 firmware to the latest version available from the manufacturer.
CVE-2022-41396 affects the Tenda AC1200 Router Model W15Ev2 running firmware version 15.11.0.10(1576).
CVE-2022-41396 is a command injection vulnerability that can compromise the security of the affected router.
Exploitation of CVE-2022-41396 could result in unauthorized access and control over the router, allowing attackers to execute arbitrary commands.